Training-Data Extraction
A model can repeat what it was shown. That includes what it should not have been shown.
Attack Library
A technical reference for the attacks RedMaw validates: how they work, what they reach and how adversarial validation proves them.
A model can repeat what it was shown. That includes what it should not have been shown.
The question is not whether the model will be wrong. It is what it can do when it is.
The model was asked to summarize a document. The document had other ideas.
The instructions were never secret. They were merely unstated.
No single message looks hostile. The sequence does the work.
One over-trusted host collects credentials from everyone who visits it.
The directory is asked to replicate. It has no reason to refuse.
A certificate authority that will issue a certificate for anyone is an identity provider for attackers.
The credential is never cracked. It is simply forwarded somewhere it still works.
An account setting chosen for convenience becomes an offline attack opportunity.
Authentication already happened. The token is the proof, and proof can be copied.
The boundary on the architecture diagram is not always the boundary in the token.
The document is working exactly as shared. That is the finding.
Nobody offboards a service account.
If you can influence what gets retrieved, you can influence what the system does with it.
The control was enabled and working. It was answered anyway.
Single sign-on concentrates trust. A broken assertion boundary concentrates the damage.
No password was stolen. One was never needed.
The domain still belongs to you. What answers on it may not.
Both requests were authorized. That was the problem.
No vulnerability class fits. The application did exactly what it was told to do.
The database was the entry point, not the destination.
Reading a file is minor. Reading the configuration that holds the credentials is not.
A flexible query language is a flexible attack surface when authorization sits in the wrong layer.
The endpoint worked as written. It was written to trust too much.
The token verified. That is not the same as the token being trustworthy.
The defect is not the format. It is that the server trusts attacker-controlled object state.
The interesting part is not that the application made an unexpected request. It is where that request could reach.
Tokens survive password resets. A stale grant is standing access with no owner watching it.
The attacker never talks to the model. The content the model reads does it for them.
Authentication proves who is calling. BOLA is what happens when nothing checks what they are allowed to touch.
Any domain account can ask for the tickets. The weakness is the password behind the service account.
Continuously test what an attacker can actually reach across your applications, SaaS identities, internal infrastructure and AI systems.